5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-58788
License Manager for WooCommerce Database
7.6
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.

CVE-2025-22352
ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Database
7.6
HIGH
EPSS
3.7%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes elex-bulk-edit-products-prices-attributes-for-woocommerce-basic allows Blind SQL Injection.This issue affects ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes: from n/a through <= 1.4.9.

CVE-2025-9072
Mattermost General
7.6
HIGH
EPSS
0.0%
2025 CWE-601 1 PoC

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.

CVE-2025-46349
yeswiki Web ⚡ nuclei
7.6
HIGH
EPSS
0.5%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.

CVE-2025-45805
Software Genérico Web
7.6
HIGH
EPSS
0.0%
2025 1 PoC

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.

CVE-2025-12397
Looker Studio Database
7.6
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no customer action is needed.

CVE-2025-22652
Payment Forms for Paystack Database
7.6
HIGH
EPSS
0.5%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kendysond Payment Forms for Paystack payment-forms-for-paystack allows SQL Injection.This issue affects Payment Forms for Paystack: from n/a through <= 4.0.1.

CVE-2025-59251
Microsoft Edge (Chromium-based) General
7.6
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE-2025-1933
Firefox General
7.6
HIGH
EPSS
0.5%
2025 1 PoC

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-30921
Newsletters Database
7.6
HIGH
EPSS
0.4%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters newsletters-lite allows SQL Injection.This issue affects Newsletters: from n/a through <= 4.9.9.7.

CVE-2025-27460
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.1%
2025 CWE-312 1 PoC

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows login. The attacker can read from and write to all files on the hard drives.

CVE-2025-56401
Software Genérico Database
7.6
HIGH
EPSS
0.1%
2025 1 PoC

ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.

CVE-2025-27461
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.3%
2025 CWE-862 1 PoC

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

CVE-2025-59461
TLOC100-100 all Firmware versions Web
7.6
HIGH
EPSS
0.1%
2025 CWE-862 1 PoC

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

CVE-2025-4123
Grafana DevOps Web ⚡ nuclei
7.6
HIGH
EPSS
5.3%
2025 CWE-79 10 PoCs

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVE-2025-46619
Software Genérico Windows
7.6
HIGH
EPSS
0.5%
2025 2 PoCs

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.

CVE-2025-24659
WPDM – Premium Packages Database
7.6
HIGH
EPSS
2.2%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Blind SQL Injection.This issue affects WPDM – Premium Packages: from n/a through <= 5.9.6.

CVE-2025-23369
Enterprise Server General
7.6
HIGH
EPSS
11.8%
2025 CWE-347 2 PoCs

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not already an existing user were not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12.14, 3.13.10, 3.14.7, 3.15.2, and 3.16.0. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2025-51503
Software Genérico Web
7.6
HIGH
EPSS
0.2%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

CVE-2025-30072
Software Genérico General
7.6
HIGH
EPSS
0.2%
2025 2 PoCs

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.